Skip to content

Commit a561c83

Browse files
committed
ci: fix zizmor issues
1 parent 555b721 commit a561c83

5 files changed

Lines changed: 52 additions & 26 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,11 +5,16 @@ on:
55
branches: [main]
66
pull_request:
77

8+
concurrency:
9+
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
10+
cancel-in-progress: true
11+
812
permissions:
913
contents: read
1014

1115
jobs:
1216
pre-commit:
17+
name: Pre-commit
1318
runs-on: ubuntu-latest
1419
steps:
1520
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -23,6 +28,7 @@ jobs:
2328
- run: pre-commit run --all-files --show-diff-on-failure --color=always
2429

2530
test:
31+
name: Test
2632
runs-on: ubuntu-latest
2733
steps:
2834
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -38,11 +44,12 @@ jobs:
3844
run: pytest
3945

4046
security:
47+
name: Security audit
4148
runs-on: ubuntu-latest
4249
permissions:
4350
contents: read
44-
pull-requests: write
45-
security-events: write
51+
pull-requests: write # Post or update PR comments with scan results from the composite action
52+
security-events: write # Upload SARIF to GitHub code scanning when the audit publishes security events
4653
steps:
4754
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
4855
with:

‎.github/workflows/integration-tests.yml‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -230,9 +230,11 @@ jobs:
230230

231231
- name: Record step outcome
232232
if: always()
233+
env:
234+
AUDIT_OUTCOME: ${{ steps.audit.outcome }}
233235
run: |
234236
mkdir -p outcome
235-
echo "${{ steps.audit.outcome }}" > outcome/outcome.txt
237+
echo "$AUDIT_OUTCOME" > outcome/outcome.txt
236238
237239
- name: Upload outcome
238240
if: always()
@@ -248,7 +250,7 @@ jobs:
248250
needs: [integration-test]
249251
runs-on: ubuntu-latest
250252
permissions:
251-
pull-requests: write
253+
pull-requests: write # Post or update the integration-test validation report on PRs
252254

253255
steps:
254256
- name: Checkout action repo
@@ -298,27 +300,28 @@ jobs:
298300
if: always() && github.event_name == 'pull_request'
299301
env:
300302
GH_TOKEN: ${{ github.token }}
303+
PR_NUMBER: ${{ github.event.pull_request.number }}
304+
GITHUB_REPOSITORY: ${{ github.repository }}
301305
run: |
302306
if [ ! -f validation-report.md ]; then
303307
echo "No report generated" >&2
304308
exit 0
305309
fi
306310
307311
MARKER="<!-- integration-test-validation-report -->"
308-
PR_NUMBER="${{ github.event.pull_request.number }}"
309312
310313
# Find existing comment with our marker
311314
COMMENT_ID=$(
312315
gh api \
313-
"repos/${{ github.repository }}/issues/${PR_NUMBER}/comments" \
316+
"repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/comments" \
314317
--paginate -q \
315318
".[] | select(.body | contains(\"${MARKER}\")) | .id" \
316319
| head -n 1
317320
)
318321
319322
if [ -n "$COMMENT_ID" ]; then
320323
gh api \
321-
"repos/${{ github.repository }}/issues/comments/${COMMENT_ID}" \
324+
"repos/${GITHUB_REPOSITORY}/issues/comments/${COMMENT_ID}" \
322325
--method PATCH \
323326
-F "body=@validation-report.md"
324327
echo "Updated existing comment ${COMMENT_ID}"

‎.github/workflows/release-please.yml‎

Lines changed: 25 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,20 @@ on:
44
push:
55
branches: [main]
66

7+
concurrency:
8+
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
9+
cancel-in-progress: true
10+
711
permissions: {}
812

913
jobs:
1014
release-please:
15+
name: Release Please
1116
runs-on: ubuntu-latest
1217
environment: release
1318
permissions:
14-
contents: write
15-
pull-requests: write
19+
contents: write # Create releases, tags, and release branches
20+
pull-requests: write # Open and update pin README pull requests
1621
steps:
1722
- uses: googleapis/release-please-action@16a9c90856f42705d54a6fda1823352bdc62cf38 # v4.4.0
1823
id: release
@@ -28,41 +33,48 @@ jobs:
2833
if: ${{ steps.release.outputs.release_created }}
2934
env:
3035
GITHUB_TOKEN: ${{ github.token }}
36+
GITHUB_REPOSITORY: ${{ github.repository }}
37+
RELEASE_MAJOR: ${{ steps.release.outputs.major }}
38+
RELEASE_TAG_NAME: ${{ steps.release.outputs.tag_name }}
3139
run: |
3240
git config user.name "github-actions[bot]"
3341
git config user.email "github-actions[bot]@users.noreply.github.com"
34-
git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@github.com/${{ github.repository }}.git"
35-
git tag -fa "v${{ steps.release.outputs.major }}" \
36-
-m "Release v${{ steps.release.outputs.tag_name }}"
37-
git push origin "v${{ steps.release.outputs.major }}" --force
42+
git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git"
43+
git tag -fa "v${RELEASE_MAJOR}" \
44+
-m "Release v${RELEASE_TAG_NAME}"
45+
git push origin "v${RELEASE_MAJOR}" --force
3846
3947
- name: Pin README to release SHA
4048
if: ${{ steps.release.outputs.release_created }}
4149
env:
4250
GH_TOKEN: ${{ github.token }}
51+
RELEASE_SHA: ${{ steps.release.outputs.sha }}
52+
RELEASE_TAG_NAME: ${{ steps.release.outputs.tag_name }}
4353
run: |
4454
sed -i -E \
45-
's|developmentseed/action-python-security-auditing@[^ ]+( # v[0-9][^ ]*)?|developmentseed/action-python-security-auditing@${{ steps.release.outputs.sha }} # ${{ steps.release.outputs.tag_name }}|g' \
55+
"s|developmentseed/action-python-security-auditing@[^ ]+( # v[0-9][^ ]*)?|developmentseed/action-python-security-auditing@${RELEASE_SHA} # ${RELEASE_TAG_NAME}|g" \
4656
README.md
4757
git add README.md
4858
git diff --cached --quiet && echo "README unchanged, skipping commit" && exit 0
49-
BRANCH="chore/pin-readme-${{ steps.release.outputs.tag_name }}"
59+
BRANCH="chore/pin-readme-${RELEASE_TAG_NAME}"
5060
git checkout -b "$BRANCH"
51-
git commit -m "chore: pin README to ${{ steps.release.outputs.tag_name }}"
61+
git commit -m "chore: pin README to ${RELEASE_TAG_NAME}"
5262
git push origin "$BRANCH"
5363
gh pr create \
54-
--title "chore: pin README to ${{ steps.release.outputs.tag_name }}" \
55-
--body "Automated: pin README SHA references to release ${{ steps.release.outputs.tag_name }}." \
64+
--title "chore: pin README to ${RELEASE_TAG_NAME}" \
65+
--body "Automated: pin README SHA references to release ${RELEASE_TAG_NAME}." \
5666
--base main \
5767
--head "$BRANCH"
5868
5969
- name: Notify tests repo to update action pin
6070
if: ${{ steps.release.outputs.release_created }}
6171
env:
6272
GH_TOKEN: ${{ secrets.TESTS_REPO_DISPATCH_TOKEN }}
73+
RELEASE_SHA: ${{ steps.release.outputs.sha }}
74+
RELEASE_TAG_NAME: ${{ steps.release.outputs.tag_name }}
6375
run: |
6476
gh api repos/lhoupert/action-python-security-auditing-tests/dispatches \
6577
--method POST \
6678
-f event_type=action-release \
67-
-F client_payload[sha]='${{ steps.release.outputs.sha }}' \
68-
-F client_payload[tag]='${{ steps.release.outputs.tag_name }}'
79+
-F "client_payload[sha]=${RELEASE_SHA}" \
80+
-F "client_payload[tag]=${RELEASE_TAG_NAME}"

‎.github/workflows/scorecard.yml‎

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,17 +7,21 @@ on:
77
# Weekly on Saturdays.
88
- cron: "30 1 * * 6"
99

10-
permissions: read-all
10+
concurrency:
11+
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
12+
cancel-in-progress: true
13+
14+
permissions:
15+
contents: read
16+
actions: read # Required by Scorecard to evaluate workflow security posture
1117

1218
jobs:
1319
analysis:
1420
name: Scorecard analysis
1521
runs-on: ubuntu-latest
1622
permissions:
17-
# Needed for Code scanning upload
18-
security-events: write
19-
# Needed for GitHub OIDC token if publish_results is true
20-
id-token: write
23+
security-events: write # Upload Scorecard SARIF to the code scanning API
24+
id-token: write # GitHub OIDC token when publish_results is true
2125

2226
steps:
2327
- name: "Checkout code"

‎action.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -89,7 +89,7 @@ runs:
8989
PR_NUMBER: ${{ github.event.pull_request.number }}
9090
INPUT_DEBUG: ${{ inputs.debug }}
9191
RUNNER_DEBUG: ${{ runner.debug }}
92-
run: uv run --no-project --with "${{ github.action_path }}" python -m python_security_auditing
92+
run: uv run --no-project --with "$GITHUB_ACTION_PATH" python -m python_security_auditing
9393

9494
- name: Upload ${{ inputs.artifact_name }}
9595
if: always()

0 commit comments

Comments
 (0)